[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

RE: SOAP-RPC and REST and security


xml field level security
It does add some overhead, but it also pays off in terms of affording rich
functionality. Our software is explicitly designed to support a vendor's
extranet for partners. The models for what privileges vendors wish to accord
to specific partners can get fairly complex, and would be unmanageable IMO
with a straightforward ACL model. The sort of business functionality
requires the sort of flexibilty that our model affords. The field level
security is accomplished by integrating it with our data access layer and
keeping developers from hitting the database directly. So the overhead is
largely just a matter of interpreting and reformulating SQL DML statements
(based on customizable business rules) rather than just passing them blindly
on through to the database.

> -----Original Message-----
> From: Bullard, Claude L (Len) [mailto:clbullar@i...]
> Sent: Wednesday, February 20, 2002 1:40 PM
> To: 'Michael Brennan'; xml-dev@l...
> Subject: RE:  SOAP-RPC and REST and security
> 
> 
> What is the impact on performance of implementing 
> field level security?  Module or record level, I 
> can understand, but field level seems to be prohibitively 
> expensive.
> 
> len
> 
> -----Original Message-----
> From: Michael Brennan [mailto:Michael_Brennan@A...]
> 
> Beyond that, many systems need security models that go beyond 
> simple ACLs. We have
> field-level security in our system, and ACLs don't cut it for 
> that. I think
> that it is increasingly common for enterprise systems to use 
> more dynamic,
> rule-based security systems, and evaluating the rules 
> properly requires
> intimate knowledge of the internals of the system.
> 

PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.